Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 2322 resultados ✕ Limpiar búsqueda
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1806
Esta semana
RSS
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17655] Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed …
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17656] Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potenti…
Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-17651] Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.7…
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-67429] Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.dow…
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR confinement, allowing attacker-controlled response bytes to be written to arbitrary filesystem paths the process can access. This issue is fixed in version 2.26.…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-67426] Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the stand…
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/verification_service.py exposes unauthenticated POST /run on 0.0.0.0:8344 and uses client-supplied callback_url for an outbound POST with X-Internal-Key: $FLYTO_RUNNER_SECRET while bypassing target_allowed, allowing unauthenticated SSRF and runner secret …
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-16326] In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless…
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-41939] Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildF…
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Ar…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-51992] SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to ex…
SQL Injection vulnerability in ClickHouse Server Versions
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-67191] Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that…
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer by sending a malformed SSH client identification string. A logic error in the recv loop's termination condition uses an incorrect OR operator where an AND operator is required, enabling exploitation on any SSH or SFTP co…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-60112] AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that…
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue arbitrary spacecraft commands by calling Sessions.create() without any credential check. Attackers can exploit the unauthenticated session issuance in Sessions.create() and subsequently invoke handle_cmd() to forward ar…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-60113] AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing au…
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that allows unauthenticated network attackers to access seven unprotected API routes by sending direct HTTP requests with no credentials. Attackers can reach the exposed SLE endpoints to start or stop Deep Space Network c…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-54735] Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Pr…
Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expos…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-14488] The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redire…
The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without any capability or ownership check, and the nonce verification in check_ajax() being gated behind is_ajax() which is false…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-14900] The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all v…
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim into a calculator formula string passed to PHP eval() inside js_to_php(), with the regex allow-list in evaluateFormula() onl…
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-58162] The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled clien…
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-58155] Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling,…
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-41920] Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic S…
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.1.4, which fixes the issue.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-57834] Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affect…
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-58150] Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade reque…
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-18191] VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated…
VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of the device.